Privacy policy
Information on the processing of personal data under Regulation (EU) 2016/679.
Last updated: 2026-09-18
This English version is a courtesy translation of the Italian text, which is the only authoritative version and prevails in case of discrepancy.
Version 1.0 — English courtesy translation, 18 September 2026
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018 ("Privacy Code")
This notice is the single document by which LX20 Law Firm S.T.A. S.r.l. describes the processing of personal data carried out within the lx20lawfirm.com website, freely accessible services, the Personal Area, the Client Area, and the newsletter service. The document is divided into a General Part, applicable to all data subjects, and two Special Parts — A (Client Portal) and B (Newsletter) — which supplement the General Part and specifically govern the processing activities proper to each context. In the event of an apparent conflict, the more specific and protective provision for the data subject shall prevail.
Definitions used in this privacy policy
"Personal Data": any identified or identifiable information, including indirectly, relating to an individual, including a personal identification number, general identification data, or Personal Data that allow for direct identification (e.g., name, VAT number, address, email address, phone number, etc.) – see Art. 4(1)(1) GDPR.
"Processing": any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Data Controller": the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Data Processor": a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the controller.
"Data Subject": an identified or identifiable natural person. In this notice, the term refers to You.
"Navigation Data": the computer systems and software procedures used to operate this Platform acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by its very nature could — through processing and association with data held by third parties — allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the Platform, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user's IT environment. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Platform and to check its correct functioning and is deleted immediately after processing.
"System Logs": for operation and maintenance purposes, this Platform and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the IP address.
General Part
1. Data Controller
The Data Controller is LX20 Law Firm S.T.A. S.r.l., a limited liability company among lawyers, with registered office in Via San Raffaele 1, 20121 Milan (MI), Italy, Tax Code and VAT No. 14389480964, enrolled in the Companies' Register of Milan Monza Brianza Lodi under no. 14389480964, R.E.A. MI-2779437, share capital € 5,000.00 fully paid-up, enrolled in the special Register of Companies among Lawyers established at the Milan Bar Association pursuant to Art. 4-bis of Law No. 247 of 31 December 2012, in the person of its legal representative *pro tempore* (hereinafter "LX20", "Firm" or "Controller").
The Firm operates through its registered office in Milan and offices in Turin and New York (United States of America), which are attributable to the same Italian legal entity.
Controller's contact details for the purposes of this document:
- Address: Via San Raffaele 1, 20121 Milan (MI), Italy
- Email: [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com)
2. Types of data processed
LX20 processes the following categories of personal data relating to natural persons with whom it comes into contact through the lx20lawfirm.com website and related services:
(a) Personal and contact data: name, surname, company name (if a legal entity), tax code, VAT number, postal address, email address, telephone numbers, professional role, place of work.
(b) Navigation data: IP address (in anonymised or pseudonymised form, where possible), browser and operating system type and version, pages visited, date and time of visit, referrer, session duration. This data is collected for IT security purposes and for aggregated statistical analysis of website usage.
(c) Data provided through contact, registration, and other forms: content of messages sent, any attached files, preferences regarding marketing communications, content of responses provided to self-service tools that may be available in the Personal Area.
(d) Personal Area access credentials: email address, password (stored in irreversibly encrypted form using cryptographic hash functions), session tokens, access logs. Any OAuth credentials from third-party providers (e.g., Google) are managed as described in §3.6.
(e) Two-factor authentication (2FA) data: TOTP secret key (encrypted at-rest), any backup codes generated upon registration, access timestamps.
(f) Professional and engagement-related data (for Firm Clients only): identification and contact data of the Client and their representatives, data relating to the assigned matter, technical and legal documentation provided or produced in connection with the engagement, any data of third parties necessary for the proper performance of the professional assignment (counterparties, authorities, external consultants). Such data is processed in accordance with the specific provisions set out in Special Part A.
(g) Data relating to anti-money laundering (AML/CDD) obligations: customer due diligence data pursuant to Legislative Decree no. 231 of 21 November 2007 and subsequent amendments, including identity documents, information on beneficial ownership, purpose and nature of the professional service, and source of funds. Such data is processed exclusively for the purposes of complying with statutory obligations.
(h) Consent-related data: record of the version of the Terms and Conditions and Privacy Policy accepted, timestamp of acceptance, marketing opt-ins/outs, log of requests to exercise rights, subsequent changes to consents given.
Special categories of data (Art. 9 GDPR): LX20 does not systematically collect data relating to health, political opinions, religious or trade union beliefs, sexual orientation, or ethnic origin through the website or the Personal Area. Should such data emerge in the context of a specific professional engagement (e.g., a labour law dispute), the processing is limited to the purposes of the engagement and is covered by the specific provisions of Special Part A.
3. Purposes of processing and legal basis
The data indicated above are processed for the following purposes, each based on its respective legal basis:
3.1 Provision of the website and public services
To allow the user to consult the website's content, download public materials, and use freely accessible services. Legal basis: Art. 6(1)(b) GDPR (performance of a contract to which the data subject is a party) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in providing a functioning and secure service).
3.2 Responding to requests via contact form
To manage correspondence with those who fill out a contact form, request information or documents. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures taken at the data subject's request).
3.3 Creation and management of the Personal Area
To allow registered users to access dedicated tools (self-help questionnaires, calculators, reserved content). Legal basis: Art. 6(1)(b) GDPR.
3.4 Transformation of the relationship from registered user to Firm Client
Should the registered user decide to formally grant a professional engagement to LX20, the data provided during registration may be supplemented and used for the management of the professional relationship. This evolution requires the signing of an engagement letter, submission of AML documentation, and acceptance of the specific regulations of Special Part A. Legal basis: Art. 6(1)(b) GDPR (performance of the professional mandate contract).
3.5 Informational communications and newsletters (only with explicit consent)
To send informational communications about the Firm's content (regulatory updates, published articles, events, market opinions) to users who have specifically given their consent. Legal basis: Art. 6(1)(a) GDPR (consent). Consent can be revoked at any time via a specific link in each communication or by accessing one's profile in the Personal Area. For detailed regulations, please refer to Special Part B.
3.6 Authentication via third-party OAuth providers (Google and similar)
To allow the user to access the Personal Area using Google credentials. In this case, LX20 receives from Google, with the user's prior consent at the time of authorization, the email address, display name, and Google profile identifier. LX20 does not have access to the Google password or other Google profile data that is not strictly necessary. Legal basis: Art. 6(1)(b) GDPR (performance of the contract requested by the data subject).
3.7 IT security and abuse prevention
To detect and counter unauthorized access attempts, service abuse, cyberattacks, and fraud. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller and third parties in the security of IT systems).
3.8 Anti-money laundering legal obligations (for Clients only)
To comply with the obligations of customer due diligence, document retention, and reporting of suspicious transactions pursuant to Legislative Decree 231/2007 and national and European anti-money laundering regulations. Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation).
3.9 Defense of a right in legal proceedings
To process personal data necessary for the establishment, exercise, or defense of a right in judicial or extrajudicial proceedings. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller) and Art. 9(2)(f) GDPR for any special categories of data.
3.10 Accounting, tax, and administrative compliance
To issue invoices, record transactions, and maintain accounting records. Legal basis: Art. 6(1)(c) GDPR.
4. Cookies and similar technologies
The use of technical, functionality, analytics, and profiling cookies is governed by the Cookie Policy available on the dedicated page, which is an integral part of this notice. For non-strictly necessary cookies, the user expresses or denies consent via the banner presented upon first access to the site. Preferences can be changed at any time via the "Manage cookie preferences" link at the bottom of each page.
5. Manner of processing and security measures
The processing of Personal Data is carried out in accordance with Art. 32 of the GDPR through automatic or manual means. Specifically, processing is carried out by means of: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data.
Personal Data are subject to both paper-based and electronic and/or automated processing using methods and tools that comply with the security measures set forth in Art. 32 of the GDPR, by persons authorized to process Personal Data under the direct authority of the Controller. As mentioned, processing may also be delegated, through specific contracts, to external parties to LX20 appointed as data processors, who will act on documented instructions from LX20 itself, as the Data Controller.
6. Communication and dissemination of data
Personal data may be communicated to the following categories of subjects:
(a) The Firm's personnel and collaborators authorized to process data pursuant to Art. 29 GDPR, bound by professional confidentiality obligations and by specific written instructions.
(b) Technology service providers acting as Data Processors pursuant to Art. 28 GDPR, appointed through a specific contractual act.
(c) External professional consultants (accountant, labor consultant, auditor, any external DPO) acting as independent Data Controllers for their respective professional purposes or as Processors in the event of a specific delegation.
(d) Judicial, administrative, and supervisory authorities when communication is required by law, regulation, an order from a competent authority, or is necessary for legal defense.
(e) Banks and payment institutions limited to the data necessary for the management of financial flows (invoicing, collections, payments).
Personal data are not subject to dissemination (understood as communication to an indeterminate number of subjects).
The updated list of external Data Processors is available at the Firm upon written request to [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com).
7. Transfer of data outside the European Union
Personal Data are stored on servers located within the European Union. It is understood that the Data Controller, should it become necessary, will have the right to move the servers also to countries outside the European Union.
Any transfers to third countries shall take place exclusively on one of the bases provided for in Chapter V of the GDPR: (i) an adequacy decision by the European Commission (Art. 45 GDPR); (ii) in the absence of an adequacy decision, appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses adopted by the European Commission, accompanied where necessary by supplementary measures; (iii) residually and for individual operations, the derogations for specific situations provided for in Art. 49 GDPR. In any case, the Controller shall pre-emptively assess the level of protection ensured in the destination country and maintain documentary evidence of the safeguards adopted.
8. Data retention period
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the principles of minimization and storage limitation (Art. 5(1)(c) and (e), GDPR). Specifically:
| Data type | Retention period | |---|---| | Navigation data (technical logs) | 12 months, unless required for the investigation of abuse | | Contact form data (without conversion into a Client) | 24 months from the last contact | | Personal Area registration data (non-Client user) | Until a deletion request is made or automatic deactivation after 24 months of continuous inactivity | | Firm's Client data | 10 years from the termination of the engagement (ordinary professional statute of limitations) — without prejudice to a longer term for specific obligations (AML: 10 years; tax and accounting obligations: 10 years from registration) | | AML due diligence data | 10 years from the date the transaction is carried out or from the termination of the relationship, pursuant to Art. 31 of D.Lgs. 231/2007 | | Consent to processing (logs) | For the duration of the purpose + 10 years for the purpose of proving that consent was obtained | | Newsletter (opt-in marketing) | Until consent is withdrawn, with active notification of termination to the user | | Data for legal defense | Until any ruling becomes final and unappealable or the legal action is extinguished |
At the end of the period, the data are deleted or irreversibly anonymized in such a way as to prevent the re-identification of the data subject.
9. Rights of the data subject
The data subject may exercise at any time the rights provided for in Articles 15 - 22 of the GDPR, and in particular:
(a) Right of access (Art. 15 GDPR): to obtain confirmation of the existence of processing and a copy of the data concerning them, together with information on the purpose, categories of data, recipients, retention period, and the origin of the data.
(b) Right to rectification (Art. 16 GDPR): to obtain the correction of inaccurate data or the completion of incomplete data.
(c) Right to erasure ("right to be forgotten", Art. 17 GDPR): to obtain the erasure of data when they are no longer necessary for the purposes for which they were collected, when the data subject withdraws consent (if consent is the legal basis), when the processing is unlawful, or when erasure is required by law. The right is subject to the limitations of Art. 17(3) of the GDPR (in particular, the Controller's legal obligations and the establishment, exercise or defence of legal claims).
(d) Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing when the data subject contests the accuracy of the data, when the processing is unlawful but the data subject opposes erasure, when the Controller no longer needs the data but the data subject requires them for the establishment, exercise or defence of legal claims, or pending the assessment of a possible objection.
(e) Right to data portability (Art. 20 GDPR): to receive the data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format and, where technically feasible, to have the data transmitted directly to another controller.
(f) Right to object (Art. 21 GDPR): to object at any time to the processing of data based on the Controller's legitimate interest, as well as to processing for direct marketing purposes (at any time and without needing to provide a reason).
(g) Right not to be subject to automated decision-making (Art. 22 GDPR): not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. LX20 does not currently use fully automated decision-making processes with such effects.
(h) Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, the data subject may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
(i) Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): the data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, [protocollo@gpdp.it](mailto:protocollo@gpdp.it), as well as to bring proceedings before the competent judicial authority.
How to exercise rights
To exercise the rights listed above, the data subject may:
- send a written request to the address [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com);
- send a registered letter with acknowledgment of receipt to the address: LX20 Law Firm S.T.A. S.r.l., Via San Raffaele 1, 20121 Milan, Italy;
- (for users of the Personal Area) use the dedicated features within their profile.
The Controller shall provide a response within one month of receiving the request, which may be extended up to a maximum of three months in cases of particular complexity (with a reasoned communication to the data subject within the first month). The exercise of rights is free of charge, except for manifestly unfounded or excessive requests (in particular because of their repetitive character), for which the Controller may charge a reasonable fee taking into account the administrative costs incurred.
10. Provision of data and consequences of refusal
The provision of data is optional, except for data necessary to provide the requested service. In particular:
- The data for registration in the Personal Area are necessary for the creation of the account: refusal to provide them makes it impossible to register.
- AML due diligence data are necessary for the conferral of the professional mandate: refusal to provide them makes it impossible to accept the engagement.
- Data for marketing purposes are always optional: refusal does not affect access to the services.
11. Minors
The website and the Personal Area are not intended for individuals under the age of 18, and LX20 does not knowingly collect personal data from minors. Should it become known that a minor's data has been processed unintentionally, the Controller will delete it without undue delay. Parents or those with parental responsibility may report the presence of such data to the Controller at the address [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com).
12. Amendments to this policy
This policy may be updated at any time to adapt to regulatory, organisational, or technological changes. The most recent version is always available at the URL https://lx20lawfirm.com/en/privacy-policy. Substantial changes will be communicated to the user with reasonable prior notice via email to the registered address and by means of a prominent notice on the website. For users of the Personal Area, substantial changes may require a new explicit acceptance before the next login.
Special Part A — Client Portal
Regarding the processing of the Client's personal data within the scope of the services provided through the Client Area of the lx20lawfirm.com website
This Special Part supplements the General Part and specifically governs the processing carried out within the scope of the professional Client-Firm relationship through the Client Area. In the event of a conflict, the more specific and protective provisions for the data subject shall prevail.
A.1 Data processed within the Client Area
In addition to the data indicated in the General Part, LX20 processes the following categories of data in the Client Area relating to the Client, its legal representatives, and the individuals involved in the engagements:
A.1.1 Client's personal and identification data
First and last name (for natural persons), company name (for legal entities), tax identification number, VAT number, registered and operational office, data of the legal representative and directors, beneficial owner, and related anti-money laundering due diligence documentation.
A.1.2 Data relating to the assigned case
Internal case reference number, subject matter of the engagement, parties involved (Client, counterparties, judicial or administrative authorities, external consultants, experts), technical and legal documentation produced or received, correspondence exchanged, schedule of deadlines, activities performed and related timing, costs and invoicing.
A.1.3 Data relating to third parties
For the proper execution of the engagement, LX20 may process personal data of third parties (counterparties, witnesses, business counterparties, authorities, beneficial owners of transactions). Such individuals are informed of the processing pursuant to Art. 14 GDPR, subject to the limitation of Art. 14(5)(b), which exempts from the information obligation where this would involve a disproportionate effort, and without prejudice to the exercise of the data subject's rights. For data obtained from public databases (Chamber of Commerce, land registries, etc.), Articles 14 and 15 of the GDPR also apply.
A.1.4 Uploaded documents and files
Files of any kind uploaded by the Client to the Client Area through the upload or messaging functions, including contractual documents, judicial acts, documentary evidence, invoices, evidentiary documents, expert reports, certifications, and AML documentation.
A.1.5 Communication data
Messages exchanged between the Client and the Firm through the internal messaging feature, attachments to communications, read receipt logs, data relating to emails forwarded by the Firm to the Client (sender, recipient, subject, date, content).
A.1.6 Access and activity data
Logs of access to the Client Area, IP address, browser, device, authenticated sessions, activities performed (document downloads, messages sent, read receipts), security events (failed login attempts, password changes, activation of two-factor authentication).
A.1.7 Special categories of data
Should the specific case require it, LX20 may process special categories of data pursuant to Art. 9 GDPR (e.g., health data in a medical-legal dispute, data relating to criminal proceedings in a related case, data concerning ethnic origin or opinions in a labour dispute). In such cases:
- the processing is carried out based on one of the lawful grounds of Art. 9(2) GDPR (in particular, letter f) the establishment, exercise or defence of legal claims);
- the data subject is specifically informed of the extent of the processing of such data;
- enhanced security measures are adopted (encryption, restricted access, audit logs).
A.2 Purposes of processing and legal basis
A.2.1 Performance of the professional mandate
Processing of data necessary for the provision of professional services as set out in the engagement letter (legal advice, drafting of documents, legal assistance in court, management of regulatory files, preparation of documents).
Legal basis: Art. 6(1)(b) GDPR (performance of the mandate agreement) and, for special categories of data, Art. 9(2)(f) GDPR.
A.2.2 Compliance with legal obligations
Compliance with the obligations imposed on the Firm by professional regulations and general law, in particular:
- Anti-money laundering obligations (D.Lgs. 231/2007 and the EU AML Package);
- Tax, accounting, and social security contribution obligations;
- Document retention obligations;
- Obligations to report to judicial, administrative, or supervisory authorities;
- Ethical obligations (Codice Deontologico Forense - Code of Conduct for Lawyers).
Legal basis: Art. 6(1)(c) GDPR.
A.2.3 Defence of a right
Processing of personal data of the Client or third parties necessary to establish, exercise, or defend a right in judicial, extrajudicial, or administrative proceedings, or for the protection of the Firm's rights.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and Art. 9(2)(f) GDPR for special categories.
A.2.4 Communication with the Client
Management of internal and external communications with the Client within the scope of the mandate, through the Client Area's messaging system, email, and telephone.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
A.2.5 Security and abuse prevention
Monitoring of access to the Client Area for security purposes, prevention of unauthorised access, detection of anomalies, and compliance audits.
Legal basis: Art. 6(1)(f) GDPR.
A.3 Professional legal privilege
Data processed within the Client-Firm relationship are covered by:
(a) Professional legal privilege pursuant to Art. 6 of Law no. 247/2012 and Art. 13 of the Codice Deontologico Forense (Code of Conduct for Lawyers). All employees, collaborators, and partners of the Firm are bound to respect this privilege.
(b) Professional secrecy under Art. 622 of the Italian Criminal Code, which criminally sanctions the disclosure of professional secrets by anyone who has become aware of a secret by reason of their status or office, profession, or art.
(c) Professional privilege enforceable against judicial authorities pursuant to Arts. 200 and 256 of the Italian Code of Criminal Procedure (c.p.p.) (with respect to documents and communications covered by privilege), within the limits provided by law.
Professional privilege applies in particular:
- in relations with third parties (counterparties, authorities without specific entitlement);
- in internal communications (the Firm's collaborators operate under a duty of professional confidentiality);
- in the retention and archiving of data (even after the termination of the mandate and for the entire mandatory retention period).
Any disclosure of data covered by privilege to third parties is made only:
- with the prior written consent of the Client;
- to comply with legal obligations (e.g., reporting to the UIF for AML purposes, pursuant to D.Lgs. 231/2007);
- to defend a right in court (within the limits of Art. 622 of the Italian Criminal Code).
A.4 Disclosure of data to third parties
In the performance of the mandate, LX20 may disclose personal data to:
(a) Staff and collaborators of the Firm authorised to process data (Art. 29 GDPR), bound by professional privilege and specific written instructions.
(b) External data processors appointed pursuant to Art. 28 GDPR:
- Technology providers (hosting, SharePoint Microsoft 365 document storage, transactional email marketing, machine translation, artificial intelligence for internal operational support);
- Professional service providers (accountant, labour consultant, potential DPO).
(c) Judicial and administrative authorities:
- Ordinary and administrative courts when required by an order from a competent authority;
- Financial Intelligence Unit (UIF) for AML reports pursuant to D.Lgs. 231/2007;
- Supervisory authorities (CONSOB, Bank of Italy, AGCM, Italian Data Protection Authority) in the cases provided for by law;
- Tax authorities for mandatory tax filing obligations.
(d) Parties involved in the mandate, within the limits necessary for the proper performance of the engagement:
- Counterparties and their lawyers (for the exchange of deeds, correspondence, documentation);
- Experts, technical consultants, authorised investigators (under a written confidentiality obligation);
- Notaries, mediators, arbitrators, conciliators involved in the case;
- Banks and payment institutions for related financial flows.
(e) The Firm's insurance company for the management of any professional liability claims.
The updated list of external data processors is available upon the Client's written request.
A.5 Transfer of data outside the EU
For transfers of personal data outside the European Economic Area, please refer to the provisions of §7 of the General Part, including the provisions regarding the Controller's New York office. For transfers specifically concerning the Client-Firm relationship (e.g., international consultations, mandates with non-EU parties, storage of documents on systems managed in the United States), LX20 assesses the applicable safeguards on a case-by-case basis and adopts supplementary measures where necessary.
A.6 Data Retention Period
Data relating to the Client and to cases are retained in compliance with the following periods:
| Data Type | Retention Period | |---|---| | Documents relating to the engagement (deeds, contracts, legal opinions) | 10 years from the final closure of the engagement (ordinary professional limitation period pursuant to Art. 2946 of the Italian Civil Code) | | AML due diligence data (CDD/EDD) | 10 years from the termination of the relationship or the execution of the transaction (Art. 31 of Legislative Decree 231/2007) | | Accounting and tax documentation | 10 years from the date of recording (Art. 2220 of the Italian Civil Code and tax regulations) | | Client Area access logs | 24 months | | Messages in the internal messaging system | For the duration of the engagement + 10 years (as part of the engagement documentation) | | Technical backups | Retained on a maximum 12-month rotation |
Once these periods have elapsed, the data is deleted or irreversibly anonymised. Longer periods may apply only in the event of:
- specific retention obligations imposed by law or authorities;
- a pending related judicial or administrative dispute;
- written agreements between the Client and the Firm.
A.7 Rights of the data subject
The Client may exercise the rights provided for in Articles 15 - 22 of the GDPR (access, rectification, erasure, restriction, portability, objection, lodging a complaint with the Supervisory Authority) in accordance with the terms and procedures described in §9 of the General Part.
A.7.1 Specifics of the Client-Firm relationship
The exercise of privacy rights within the Client-Firm relationship is subject to certain specific limitations dictated by the professional nature of the relationship and applicable regulations:
- Right to erasure: does not apply to AML due diligence data for the 10-year mandatory retention period, nor to engagement documents for the limitation period, nor to data necessary for the defence of a legal claim.
- Right of access: full for the Client with respect to their own data. For third-party data present in the case file, access is permitted within the limits of professional secrecy and the rights of third parties (e.g., opposing party's deeds, communications with other lawyers, documents of parties involved in the engagement).
- Right to data portability: applicable to data provided by the Client in a structured format, but not to documents produced by the Firm in the performance of the engagement (deeds, opinions, expert reports — which are covered by the Firm's copyright).
- Right to object: not applicable to processing necessary for the performance of the engagement and for legal obligations.
A.7.2 Internal communications via the Client Area
The messaging functions of the Client Area are a tool for professional communication between the Client and the Firm, not a general channel for technical support or the exercise of privacy rights. To exercise privacy rights, the data subject must use the dedicated channels indicated in §9 of the General Part.
A.8 Specific security measures for the Client Portal
In addition to the general measures (§5 of the General Part), enhanced measures are adopted for the Client Area:
- Two-factor authentication (2FA) available for every user, recommended for accessing the Portal;
- At-rest encryption of uploaded documents, with keys managed separately from application data;
- Immutable audit log of operations performed on the case file (access, downloads, uploads, modifications);
- Dynamic watermarking of downloaded documents with a unique Client identifier, for traceability in the event of a leak;
- Logical segregation of different Clients' case files at the database level using a Row-Level Security policy;
- Strict access control (RBAC + principle of least privilege) for the Firm's personnel;
- Daily data backup with retention on a separate system;
- Internal Data Breach procedure (notification to the authority within 72 hours, communication to the Client in case of high risk).
A.9 Provision of data and consequences of refusal
The provision of data requested for the performance of the engagement is mandatory for the purposes set out in §A.2.1 and §A.2.2. Refusal to provide such data makes it impossible to accept or continue the engagement. For AML obligations, refusal entails the Firm's mandatory abstention from performing the professional service pursuant to Articles 17 and 35 of Legislative Decree 231/2007.
A.10 Amendments to the notice
This Special Part is an integral part of the single information notice and follows the publication and update procedures set out in §12 of the General Part. Substantial amendments are communicated to the Client via email and/or a notice in the Client Area.
A.11 Contacts
For any request or to exercise rights relating to the processing of data within the Client Portal:
- Email: [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com)
- Address: LX20 Law Firm S.T.A. S.r.l., Via San Raffaele 1, 20121 Milan, Italy
- Via the internal messaging system of the Client Area (for operational communications regarding the relationship, not for privacy requests)
In case of a complaint, the Client may contact the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — [protocollo@gpdp.it](mailto:protocollo@gpdp.it)) or take legal action before the judicial authorities.
Special Part B — Newsletter
Pursuant to Articles 13 of Regulation (EU) 2016/679 (GDPR) and 130 of Legislative Decree 196/2003 (Privacy Code)
B.1 Data processed
For sending the LX20 newsletter, LX20 processes:
- Email address (mandatory);
- First and last name (optional, for personalization purposes);
- Date and time of subscription to the newsletter (log for demonstrating consent pursuant to Art. 7(1) GDPR);
- Version of the privacy policy accepted at the time of subscription;
- Aggregated behavioral data related to the emails sent: date and time of opening, clicks on links, spam reports, any unsubscriptions. This data is collected through the transactional email sending platform (Brevo SAS) for statistical and service improvement purposes. No individualized profiling is carried out: behavioral data is used only in aggregate form or for the technical management of the relationship (e.g., detecting no longer active addresses).
B.2 Purposes of processing and legal basis
The data is processed for the following purposes:
(a) Sending the periodic LX20 newsletter containing: regulatory and legislative updates, articles published by the Firm, notification of publications, invitations to professional events, and educational and informational content in the Firm's practice areas.
Legal basis: Art. 6(1)(a) GDPR (free, specific, informed, and unambiguous consent given upon subscription).
(b) Aggregated measurement of the newsletter's effectiveness (average open rate, average click rate, unsubscribe rate) for statistical and service improvement purposes.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller to measure the effectiveness of its communications in aggregate form).
(c) Technical management of subscriptions and unsubscriptions, compliance with GDPR transparency obligations.
Legal basis: Art. 6(1)(c) GDPR.
B.3 Newsletter characteristics
- Indicative frequency: bimonthly or quarterly (the Firm may vary the frequency without prior notice, without prejudice to the right to unsubscribe).
- Content: regulatory updates in LX20's practice areas (fintech, M&A, banking, regulated finance, digital assets, AI Act, DORA), technical commentary, notification of publications, events, and initiatives of the Firm.
- Sending method: via email, in HTML and text format, with clickable links to the website.
- Sender identification: the sender is clearly identified as "LX20 Law Firm" and the email originates from a domain owned by the Firm.
The newsletter does not contain third-party advertising, aggressive commercial offers, or products or services other than professional information.
B.4 Subscription and consent methods
Subscription to the newsletter is carried out through one of the following methods:
(a) Subscription form on the website with email confirmation ("double opt-in" procedure): the user enters their email address, receives a confirmation message with an activation link, and completes the subscription by clicking the link. This procedure ensures that consent has been knowingly given by the actual owner of the email address.
(b) Ticking the appropriate checkbox during registration for the Personal Area, separate and not pre-selected from the acceptance of the Terms and Conditions and the acknowledgment of this Policy: acceptance of the Terms is a condition for using the services, acknowledgment of the Policy does not constitute consent, and subscription to the newsletter is an optional and separate consent.
(c) Ticking the box during login via an OAuth provider (e.g., Google), managed on the consent completion page after the first login.
In all cases:
- Consent is free: it is not a condition for accessing other services on the site or for requesting information or professional advice.
- Consent is specific: it is collected separately for the purpose of sending the newsletter.
- Consent is informed: the user has access to this policy before giving consent.
- Consent is unambiguous: it requires a positive action (ticking a box or confirming by clicking a link).
B.5 Withdrawal of consent and unsubscription
The user may withdraw their consent at any time, without needing to provide a reason and without any cost or prejudicial consequence.
Unsubscription methods:
(a) "Unsubscribe" link in every newsletter: present in the footer of every email sent. A single click automatically cancels the subscription, usually with immediate confirmation.
(b) From the user's profile page in the Personal Area: under "Communication Preferences," the user can untick the box for the newsletter. The change is effective immediately.
(c) Written request to the address [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com) with the subject "Newsletter Unsubscription". The Controller will process the request within 72 hours of receipt.
The withdrawal of consent leads to the immediate cessation of sending promotional communications. The data related to the subscription log (date, time, version of the policy accepted) are retained for the periods specified in §B.7 for the purpose of demonstrating historical consent, pursuant to Art. 7(1) GDPR.
The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
B.6 Communication and dissemination of data
The data is processed by:
(a) Firm personnel authorized to process data (Art. 29 GDPR).
(b) External data processors appointed pursuant to Art. 28 GDPR:
- Brevo SAS (formerly SendinBlue), 7 Rue de Madrid, 75008 Paris, France — transactional email sending and list management platform. Brevo operates in compliance with the GDPR, with servers located in the European Union.
For other categories of Processors, please refer to §6 of the General Part.
The data is not disseminated or transferred to third parties for marketing purposes.
B.7 Data retention period
Data are retained for the following periods:
| Type | Retention | |---|---| | Subscribed email address + personal data | Until consent is withdrawn (unsubscription) | | Subscription log (date, time, policy version) | 10 years from the date of subscription, for the purpose of demonstrating consent pursuant to Art. 7(1) GDPR | | Unsubscription log | 10 years from the date of unsubscription, for the purpose of demonstrating the termination of processing | | Aggregated behavioural data (opens, clicks) | 24 months from the sending of the individual communication, in a form no longer associable with the data subject's identity |
Upon expiry of these periods, the data are deleted or irreversibly anonymised.
B.8 Data subject's rights
The data subject has the right, at any time, to:
- Access their data (Art. 15 GDPR).
- Obtain the rectification of inaccurate or incomplete data (Art. 16).
- Obtain the erasure of their data, within the limits of Art. 17 GDPR (full erasure is limited by the log data to be retained for the purpose of demonstrating consent).
- Restrict processing (Art. 18).
- Object to processing at any time, including the right to object to direct marketing (Art. 21(2) GDPR — an unconditional right that does not require justification).
- Receive the data in a structured format and, where applicable, transmit them to another controller (Art. 20).
- Withdraw consent at any time, in accordance with the methods set out in §B.5.
- Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
To exercise these rights, the data subject may write to [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com) or use the self-service features in the Personal Area (if registered).
B.9 Provision of data
The provision of the email address is necessary to provide the newsletter service. Any refusal will make it impossible to subscribe. The provision of first and last name is, however, optional.
B.10 Data transfers outside the EU
For data transfers outside the European Economic Area, please refer to §7 of the General Part. At the time of writing, newsletter data are processed exclusively by providers with servers located in the European Union (France for Brevo).
B.11 Changes to the policy
This Special Part is an integral part of the single policy and follows the publication and update methods set out in §12 of the General Part. The user will be informed of any substantial changes by email or by a notice on the dedicated page.
B.12 Contacts
For any request:
- Email: [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com)
- Address: LX20 Law Firm S.T.A. S.r.l., Via San Raffaele 1, 20121 Milan, Italy
*Policy drafted in compliance with Reg. (EU) 2016/679 (GDPR), Legislative Decree 196/2003 as amended (Codice Privacy), Legislative Decree 231/2007 (AML), Law 247/2012 (ordinamento forense), and the Codice Deontologico Forense (Forensic Code of Conduct).*